Maserati Connect Potential Security Issue

MrMickS

Member
Messages
3,959
The latest Maserati, and all new ones going forward, come with Maserati Connect which allows you to connect to the car remotely via an app on your phone/watch. According the Maserati this gives you "the luxury of being in control". The system is the same as My Alfa Connect which has been in all Alfa Romeo cars since MY21.

"What's wrong with that?", I hear you say. Let me tell you a tale...

We recently swapped the Stelvio for an MY22 Giulia. Lovely car, much better interior than the old one. Flipping through the screens in the infotainment system we see the Alfa Connect screen. It says that it's connected. Contacting the dealer we bought the car from they said, "the previous owner must have forgotten to disconnect it, but its ok because they've overridden it and you should get an email with instructions on how to connect coming through.".

The email duly arrived, instructions followed, and the car appears in the My Alfa Connect app.

From the app you are able to see the fuel level, I guess this will be important when checking battery level in our electric cars, and location. Hang on, that means that until the dealer disconnected the previous owner they could see where the car was. Presumably they'd be able to track it back to our house.

Then looking at the app, and confirmed by the Maserati Connect System page, it gets worse.

REMOTE VEHICLE OPERATIONS

From the Maserati Connect app, you can: lock & unlock doors, flash vehicle's lights, beep vehicle's horn, turn the engine on/off.

So someone with the car connected to their account could see the location of the car, unlock it, start it, and drive off. Or, alternatively, if someone could hack into the Alfa/Maserati Connect account using username and password, they could find the car and steal it.

I'm still trying to work out what is wrong with pressing a button on a key to lock/unlock and using a key in the ignition to allow the car to be started.

tl;dr If you have a Maserati with the Maserati Connect system make sure that a previous owner isn't still connected to it and make sure you secure your username/password.